PDA

View Full Version : Revirgin 1.2 beta just released


tsehp
September 14th, 2001, 18:58
1.2 beta
The tracer is entirely redesigned, and a device driver has been added to support win2k + future xp.
A function Ďapi emulatorí is added, it resolve asprotectís small api emulation, like getcommandlineA or getProcessId for example, use them after a resolve again or unsuccessfull tracing.

A tracer is added, itís provided to help you find the targetís oep and dump the app (using procdump actually)

see the readme.doc for details

The install is now on a msi, done on a cracked wise installer but uncomplete, so you'll have to bear the evaluation messages when you install it for a little time.

beta available at tsehp.cjb.net

regards,

tsehp

Js
September 15th, 2001, 04:55
Hiya tsehp,
Sounds good. Do I need a tracer to find where to get it from?
regards

tsehp
September 15th, 2001, 06:21
Quote:
Originally posted by Js
Hiya tsehp,
Sounds good. Do I need a tracer to find where to get it from?
regards


he he ! at usual place : tsehp.cjb.net on the main page !

SpeKKeL
September 16th, 2001, 14:18
Don't know if i'am the only one but
using the api/emulator revirgin crashes..
Tried several times on aiswpp.exe as you explained
but it keeps going wrong when i use this option.
Have reinstalled and throwed away urlier versions of
thread and tracer.dll.
Using w98 (first ed.)With or without icedump running.
I didn't got any error messages, revirgin freezes......brrrr.

Just to inform you and to get some response from other
users...

Spekkel



tsehp
September 16th, 2001, 17:42
Quote:
Originally posted by SpeKKeL
Don't know if i'am the only one but
using the api/emulator revirgin crashes..
Tried several times on aiswpp.exe as you explained
but it keeps going wrong when i use this option.
Have reinstalled and throwed away urlier versions of
thread and tracer.dll.
Using w98 (first ed.)With or without icedump running.
I didn't got any error messages, revirgin freezes......brrrr.

Just to inform you and to get some response from other
users...

Spekkel




ok, give me more details :
aiswpp : what iat did you tried with the api emulator

w98 : don't have it but only win_me, it freezes when ? when loading when resolving ?

SpeKKeL
September 17th, 2001, 02:04
Ok,

tried with : oep 51a59c
start 124190
length 7b8

After iat-resolver and resolve again there are 7 entries open:

170c548 red/emul.
170c90c red/emul.
170c960 (no comment)
170c968 (no comment)
170c928 (no comment)
170c958 (no comment)
170c974 (no comment)

Now when i choose one of them (doesn't matter which one)
right-click and try api-emul revirgin freezes..

Spekkel

SpeKKeL
September 17th, 2001, 02:22
BTw when i use the option trace, only the redirected (get command linea, getcurrentprocessid, etc) 5 entries are still left.

Spek

tsehp
September 17th, 2001, 14:17
thanks spekkel,

download the new msi now, it's fixed. It was only a problem when the tracer was unloading itself from main target.

The 5 entries left are emulated api's.

try them, you can all select them and do at once.

regards

SpeKKeL
September 18th, 2001, 09:00
Okeeee

All goes well, no more freezing allllll resolved !

Thanks ....Spekkel

tsehp
September 18th, 2001, 15:49
keep looking for the build versions now...

the goal is to add now some dumping features on the tracer, and also to prevent some alexey tricks, I'll give more details if you email me

actually no known targets resisted to this new beta, the goal is to find one... (what a self sufficient lamer I am... )